-

CVE-2022-50077

In the Linux kernel, the following vulnerability has been resolved:

apparmor: fix reference count leak in aa_pivotroot()

The aa_pivotroot() function has a reference counting bug in a specific
path. When aa_replace_current_label() returns on success, the function
forgets to decrement the reference count of “target”, which is
increased earlier by build_pivotroot(), causing a reference leak.

Fix it by decreasing the refcount of “target” in that path.

Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version < d53194707d2a1851be027cd74266b96ceff799d3
Version 2ea3ffb7782a84da33a8382f13ebd016da50079b
Status affected
Version < f4d5c7796571624e3f380b447ada52834270a287
Version 2ea3ffb7782a84da33a8382f13ebd016da50079b
Status affected
Version < ef6fb6f0d0d8440595b45a7e53c6162c737177f4
Version 2ea3ffb7782a84da33a8382f13ebd016da50079b
Status affected
Version < 2ceeb3296e9dde1d5772348046affcefdea605e2
Version 2ea3ffb7782a84da33a8382f13ebd016da50079b
Status affected
Version < 64103ea357734b82384c925cba4758fdb909be0c
Version 2ea3ffb7782a84da33a8382f13ebd016da50079b
Status affected
Version < 3ca40ad7afae144169a43988ef1a3f16182faf0a
Version 2ea3ffb7782a84da33a8382f13ebd016da50079b
Status affected
Version < 11c3627ec6b56c1525013f336f41b79a983b4d46
Version 2ea3ffb7782a84da33a8382f13ebd016da50079b
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 4.14
Status affected
Version < 4.14
Version 0
Status unaffected
Version <= 4.14.*
Version 4.14.291
Status unaffected
Version <= 4.19.*
Version 4.19.256
Status unaffected
Version <= 5.4.*
Version 5.4.211
Status unaffected
Version <= 5.10.*
Version 5.10.138
Status unaffected
Version <= 5.15.*
Version 5.15.63
Status unaffected
Version <= 5.19.*
Version 5.19.4
Status unaffected
Version <= *
Version 6.0
Status unaffected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.04% 0.094
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String